-
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-EDR tactic linked to the operation. The intrusion failed to encrypt files after the stripped-down…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launch up to 100 encryption threads, a design that compresses the time defenders have to detect and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified Kimwolf v7 build shows the Android and IoT botnet shifting from an all-in-one compromise toolkit into a more specialized DDoS and proxy-relay payload. The latest variant removes embedded scanning, exploitation and brute-force logic, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A China-linked threat actor has reportedly utilized a multi-agent artificial intelligence framework to conduct a nearly autonomous intrusion campaign targeting government entities in Taiwan and across Asia. This operation demonstrates how agentic AI ca…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Phantom Stealer is a .NET-based credential-harvesting malware that combines PNG-backed payload concealment, PowerShell-driven process injection, and telemetry suppression to steal passwords, browser data, cryptocurrency wallets, and sensitive local fil…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated threat campaign, referred to as “City-Forum,” is targeting publicly accessible Salesforce Experience Cloud sites and ServiceNow Service Portals, aiming to enumerate and extract data exposed to anonymous users. Security firm Reco, which …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Palo Alto Networks has released security advisories for multiple vulnerabilities in the GlobalProtect App that could allow a local attacker to elevate their privileges to SYSTEM on Windows or to root on Linux and macOS systems. These advisories were pu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has released version 7.0.4 to address a high-impact authenticated remote code execution (RCE) vulnerability. This flaw could allow users with Author-level privileges or higher to execute code on affected websites. The vulnerability, tracked a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Nightmare-Eclipse, also known as Chaotic Eclipse, has released a new Windows privilege escalation exploit named ShieldBreak. This exploit claims to bypass Microsoft’s July 2026 fix for the RoguePlanet Windows Defender vulnerability,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat researchers have identified an active campaign exploiting the critical VMware vCenter vulnerability CVE-2026-59310, with 361 victim IP addresses observed across 47 countries. This campaign reportedly began within days of the public disclosure an…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


